Vulnerabilities > Cisco > Nexus 7000 > High

DATE CVE VULNERABILITY TITLE RISK
2019-03-08 CVE-2019-1608 Command Injection vulnerability in Cisco Nx-Os
A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system of an affected device.
local
low complexity
cisco CWE-77
7.2
2019-03-08 CVE-2019-1607 Command Injection vulnerability in Cisco Nx-Os
A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands on the underlying operating system of an affected device.
local
low complexity
cisco CWE-77
7.2
2019-03-08 CVE-2019-1605 Improper Input Validation vulnerability in Cisco Nx-Os
A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary code as root.
local
low complexity
cisco CWE-20
7.2
2019-03-08 CVE-2019-1604 Improper Authorization vulnerability in Cisco Nx-Os
A vulnerability in the user account management interface of Cisco NX-OS Software could allow an authenticated, local attacker to gain elevated privileges on an affected device.
local
low complexity
cisco CWE-285
7.2
2019-03-08 CVE-2019-1601 Improper Access Control vulnerability in Cisco Nx-Os
A vulnerability in the filesystem permissions of Cisco NX-OS Software could allow an authenticated, local attacker to gain read and write access to a critical configuration file.
local
low complexity
cisco CWE-284
7.2
2019-03-07 CVE-2019-1599 Resource Management Errors vulnerability in Cisco Nx-Os
A vulnerability in the network stack of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on the affected device.
network
low complexity
cisco CWE-399
7.8
2019-03-06 CVE-2019-1593 Permissions, Privileges, and Access Controls vulnerability in Cisco Nx-Os
A vulnerability in the Bash shell implementation for Cisco NX-OS Software could allow an authenticated, local attacker to escalate their privilege level by executing commands authorized to other user roles.
local
low complexity
cisco CWE-264
7.2
2018-06-21 CVE-2018-0337 Incorrect Authorization vulnerability in Cisco Nx-Os
A vulnerability in the role-based access-checking mechanisms of Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands on an affected device.
local
low complexity
cisco CWE-863
7.2
2018-06-21 CVE-2018-0306 OS Command Injection vulnerability in Cisco Nx-Os
A vulnerability in the CLI parser of Cisco NX-OS Software could allow an authenticated, local attacker to perform a command-injection attack on an affected device.
local
low complexity
cisco CWE-78
7.2
2018-06-20 CVE-2018-0314 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Cisco products
A vulnerability in the Cisco Fabric Services (CFS) component of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, remote attacker to execute arbitrary code on an affected device.
network
low complexity
cisco CWE-119
7.5